Privacy Policy & Data Protection
At QuickMoment, privacy is built into our core engineering. Learn how we safeguard your personal information, client portraits, and biometric facial vector calculations under GDPR, CCPA/CPRA, and Illinois BIPA standards.
We never sell, rent, monetize, or trade client photos, contact details, or facial embeddings to any third parties.
Your clients' portraits and selfies are strictly quarantined; they are never used to train public generative AI algorithms.
All image files and database records are safeguarded with AES-256 at rest and TLS 1.3 in transit.
Facial vectors and temporary guest query selfies are automatically deleted upon gallery expiration or studio request.
QuickMoment operates as a Data Processor / Service Provider on behalf of our studio customers (who act as the Data Controllers). We process your event photos and generate mathematical facial coordinates solely to match guests with their portraits in real time. We do not track guests across unrelated venues, we do not build public facial databases, and we never commercialize biometric data.
1 Introduction & Roles Under Data Protection Laws
This Privacy Policy explains how Quick Moment Technologies Inc. ("QuickMoment", "we", "us", "our") handles personal information collected via our website (https://quickmoment.in/), studio dashboards, mobile client portals, and cloud APIs.
Depending on your relationship with QuickMoment, data protection regulations distinguish between two primary roles:
- Studio Subscribers (Data Controllers): When event photographers, photo studios, or agencies upload photographs of attendees, they act as the Data Controller under GDPR, CCPA, and applicable state privacy laws.
- QuickMoment (Data Processor / Service Provider): QuickMoment processes event media, performs facial geometric vector indexing, and transmits guest galleries strictly pursuant to the instructions and subscription terms configured by the studio controller.
2 Information We Collect
We collect information across three functional categories:
A. Studio Account & Billing Information
When you register a studio workspace or purchase a subscription, we collect your first and last name, studio/business name, corporate email address, telephone number, encrypted password hash, and payment records. When using Google Single Sign-On (OAuth 2.0), we receive your verified Google email address and public display name.
B. Event Media & EXIF Metadata
High-resolution photographs and previews uploaded via wireless tethering, folder sync, or web uploader. We process image metadata including camera model (Sony, Canon, Nikon), lens focal length, exposure time, aperture, ISO, and file capture timestamps to power smart event album filters.
C. Guest Interaction & Query Data
When an attendee scans an event QR standee or accesses a public gallery:
- Selfie Image Query: If a guest utilizes AI facial search, they submit a live camera selfie to locate their photos.
- WhatsApp / Phone Number: If a guest requests automated WhatsApp delivery, we collect their phone number solely to transmit their curated gallery link.
- Technical Diagnostics: IP address, browser user-agent, operating system, and referral headers for security monitoring and fraud prevention.
3 Biometric Information Notice (BIPA, Texas CUBI & GDPR Art. 9)
This section serves as an explicit disclosure under the Illinois Biometric Information Privacy Act (740 ILCS 14/1 et seq., "BIPA"), the Texas Capture or Use of Biometric Identifier Act ("CUBI"), and Article 9 of the EU/UK General Data Protection Regulation ("GDPR").
When face recognition is enabled for an event, our neural networks detect facial bounding boxes and compute 512-dimensional mathematical numerical vector embeddings. These floating-point numbers describe geometric facial characteristics (such as the relative distance between eye pupils, nose bridge, and jawline contours).
Specific Biometric Disclosures:
- Purpose of Collection: Biometric vectors are generated for the sole and exclusive purpose of matching event attendees with their photographs in the corresponding event album.
- No Commercial Sale: QuickMoment never sells, leases, trades, or profits from any biometric identifier or biometric information.
- Retention Schedule: Mathematical facial vectors are retained only for the duration of the active event gallery. Facial vectors are permanently destroyed upon:
- The studio deleting the event or associated photos;
- The expiration of the studio's contracted gallery retention period; or
- Within a maximum of thirty (30) days following the termination of the studio account.
- Ephemeral Query Selfies: A guest selfie uploaded to perform a facial search is processed in volatile memory and purged within twenty-four (24) hours of query execution.
- Studio Responsibility: Studios operating events in jurisdictions requiring written biometric notices and releases (including Illinois and Texas) are responsible for posting appropriate attendee signage or obtaining client agreements before enabling facial recognition.
4 How We Use Collected Information
We process personal and event data for legitimate business purposes:
- Core Service Delivery: Providing real-time wireless camera tethering, thumbnail rendering, AI face matching, and guest photo viewing;
- Communication: Transmitting transactional account emails, password reset verifications, quota threshold alerts, and subscription receipts;
- Automated Guest Delivery: Sending private WhatsApp or SMS gallery links requested by event attendees;
- System Security & Fraud Prevention: Protecting our infrastructure against unauthorized intrusion, distributed denial-of-service (DDoS) attacks, and account takeover;
- Regulatory Compliance: Fulfilling statutory accounting, tax, and legal obligations under applicable law.
5 Camera Wireless Tethering & Edge Sync
When utilizing QuickMoment Wireless Tethering (compatible with Sony, Canon, and Nikon camera bodies via PTP/IP and FTP):
- Encrypted Transport: Wireless photo transfers from your tethering station or camera to QuickMoment cloud edge nodes are secured using modern TLS 1.3 encryption.
- Local Cache Management: Desktop bridge software stores temporary local cache files on your device. You retain full control to clear local cache directories at any time through application settings.
6 Guest QR Codes & WhatsApp Notifications
QuickMoment enables zero-friction photo retrieval for wedding, corporate, marathon, and graduation attendees through branded QR standees.
- No Forced App Download: Guests access their gallery directly within their native mobile browser without installing third-party native apps.
- Explicit WhatsApp Opt-In: Phone numbers entered by guests to receive WhatsApp photo links are used exclusively for that specific event transaction. We never add guest phone numbers to marketing broadcast lists or share them with third-party advertisers.
7 Third-Party Subprocessors & Cloud Infrastructure
QuickMoment partners with industry-leading infrastructure providers to deliver high availability and security. All subprocessors are vetted for compliance with SOC 2, ISO 27001, and GDPR Data Processing Addendums (DPAs):
| Subprocessor | Purpose / Function | Data Location | Security Certifications |
|---|---|---|---|
| Amazon Web Services (AWS) | High-durability cloud storage (S3), GPU vector clustering & compute | United States / Global Regions | SOC 1/2/3, ISO 27001, FedRAMP |
| Cloudflare Inc. | Global CDN, edge SSL termination, DDoS protection, Web Application Firewall (WAF) | Global Edge Network | SOC 2 Type II, ISO 27001, PCI-DSS |
| Google Cloud Platform | OAuth 2.0 authentication verification & optional Drive backup integrations | United States / EU | SOC 2/3, ISO 27001, HIPAA |
| Cashfree Payments | Subscription billing, automated invoices & secure payment processing | India / Global | PCI-DSS Level 1, ISO 27001 |
| Meta / WhatsApp Business API | Automated guest gallery delivery notifications | United States / Global | SOC 2, Meta Enterprise Security |
8 Data Retention & Automated Purging Schedules
We maintain strict data minimization and scheduled purge policies:
- Active Studio Accounts: Event photographs, face vectors, and client galleries remain accessible as long as your studio subscription remains active and within allocated storage limits.
- Manual Studio Deletion: When a studio deletes an event or individual photo, all associated thumbnail assets, full-resolution files, and facial vector embeddings are queued for immediate deletion and purged from active servers within forty-eight (48) hours.
- Cancelled / Expired Studios: Following subscription cancellation, studio assets are preserved for a thirty (30) day grace period to allow data export, after which all media and biometric vectors are permanently sanitized.
9 Security Architecture & Encryption Standards
QuickMoment implements comprehensive technical, physical, and administrative safeguards designed to prevent unauthorized access, alteration, or disclosure of customer data:
- Encryption in Transit: All HTTP network traffic is strictly enforced via HTTPS utilizing Transport Layer Security (TLS 1.3) with HSTS preloading.
- Encryption at Rest: All stored original photographs, generated thumbnails, and database snapshots are encrypted using AES-256 (Advanced Encryption Standard).
- Access Control: Production servers and vector databases require hardware-token multi-factor authentication (MFA) and are restricted by role-based least-privilege security policies.
- Database Isolation: Multi-tenant studio data is partitioned with strict tenant ID scoping enforced at the application and query layers.
10 Your Privacy Rights (GDPR, CCPA/CPRA, State Laws)
Depending on your jurisdiction of residence, you possess specific statutory rights regarding your personal data:
- Right to Access & Portability: You may request a copy of the personal data QuickMoment holds about you in a structured, machine-readable format.
- Right to Rectification: You have the right to correct inaccurate or incomplete studio account records.
- Right to Erasure ("Right to be Forgotten"): You may request the permanent deletion of your account, event media, or biometric face vectors.
- Right to Restrict or Object: You may object to certain data processing activities under legitimate interest provisions.
- Non-Discrimination: We will never discriminate against you (in pricing, features, or service quality) for exercising your statutory privacy rights.
To exercise any of these rights, please email our privacy team at support@quickmoment.in. We verify and respond to authenticated requests within thirty (30) calendar days.
11 Children's Privacy Notice (COPPA)
QuickMoment is a commercial SaaS platform designed for professional photographers and event agencies; it is not directed to children under the age of 13.
When event photographers photograph family events (such as birthday celebrations or school sports) involving minors, the studio controller warrants that they have obtained parental consent or school authorization. If QuickMoment discovers that personal data from a child under 13 was provided without verified parental consent, we will promptly delete such records.
12 Policy Updates & Data Protection Officer Contact
We may periodically revise this Privacy Policy to reflect platform features, security enhancements, or legal standards. Material revisions will be accompanied by an updated effective date and prominent dashboard notification.
Data Protection Officer (DPO) & Privacy Desk
Attention: Data Protection & Biometric Privacy Officer
Email: support@quickmoment.in
Help Desk: https://quickmoment.in/contact.php